Audit & Assurance
ERP Pre and Post Implementation Review
The controls in an ERP are configured once, usually under deadline pressure, and then inherited for a decade. Independent review before go-live is materially cheaper than remediation afterwards.
Pre-implementation: go-live readiness
Conducted before cut-over, while findings can still change the outcome. Because the system is not yet live, conclusions are on design rather than operating effectiveness — we state that explicitly in the report rather than implying assurance we cannot give.
- Programme governance, steering effectiveness and decision authority.
- Requirements traceability — whether what is being built is what was approved.
- Configuration of application controls: approval workflows, tolerance limits, three-way match, validation rules.
- Segregation of duties in the role and authorisation design, tested for conflicting combinations before they are granted.
- Data migration controls — completeness, accuracy, reconciliation and the sign-off trail.
- Interface design and reconciliation controls between the ERP and surrounding systems.
- Testing adequacy — whether UAT actually covered the control requirements, with evidence.
- Cut-over plan, fallback plan, and the criteria on which go-live will be authorised.
- Readiness of security administration, change management and support processes for day one.
Post-implementation review
Usually three to six months after go-live, once a full period cycle has run. Here we can test operating effectiveness: whether the configured controls are working, whether workarounds have emerged, whether emergency access granted during cut-over was ever revoked, and whether the segregation of duties design survived contact with reality.
Two engagements, two different conclusions
Platforms
SAP including S/4HANA, Oracle E-Business Suite and Fusion, Microsoft Dynamics 365, and core banking and insurance platforms. We audit the control configuration; we do not implement, and we hold no implementation partner status with any vendor — so the finding is not shaped by a channel relationship.
How the engagement runs
-
1
Programme understanding
Review scope, timeline, governance and the control requirements the programme committed to deliver.
-
2
Control design review
Assess configured application controls and the role and authorisation design against the risks they must address.
-
3
Segregation of duties analysis
Systematically test the role design for conflicting access combinations before roles are provisioned.
-
4
Data migration assurance
Review reconciliation controls, sample-test migrated data and assess the sign-off trail.
-
5
Readiness assessment
Evaluate testing evidence, cut-over readiness and the state of supporting processes.
-
6
Reporting
Report against the go-live decision date, so findings arrive while they can still change something.
What you receive
Frequently asked questions
Related services
Related regulatory frameworks
Need an independent view?
Tell us the scope, the regulator and the deadline. We will come back with an approach, a team and a fee estimate.
Request a proposal